Enabling ACL Logging

For an ACL to generate a syslog entry, match statements to be logged must contain the log keyword, and logging must be enabled for the ACL when it is bound to an interface, LAG, VLAN, or selective ports of a VLAN with the keywords logging enable included in the binding command.

Perform the following steps to configure ACL logging.

  1. Enter global configuration mode.
    device# configure terminal
  2. Enter configuration sub-mode for a new or existing ACL.
    • To configure an IPv4 ACL, use the appropriate ip access-list command followed by the name or ID.
      device(config)# ip access-list extended v4track
      device(config-ipacl-v4track)#
    • To configure an IPv6 ACL, use the ipv6 access-list command followed by the name or ID.
      device(config)# ipv6 access-list v6track
      device(config-ipv6-access-list v6track)#
    • To configure a MAC ACL, use the mac access-list command followed by the name.
      device(config)# mac access-list mactrack
      device(config-macl-mactrack)# 
  3. Create or update ACL filter statements with the log keyword to indicate which matches should be included in the syslog.
    The following example configures logging for an IPv4 extended ACL permit action.
    device(config)# ip access-list extended v4track
    device(config-ext-ipacl-vtrack)# permit host 10.157.22.26 any log
    
    The following example configures logging for an IPv6 ACL permit action.
    device(config)# ipv6 access-list v6track
    device(config-ipv6-access-list v6track)# permit ipv6 host 10.158.10.10 any log
    
    The following example configures logging for a MAC ACL deny action.
    device(config)# mac access-list mactrack
    device(config-macl-mactrack)# deny any 0000.0000.0088 0000.0000.1111 log
    device(config-macl-mactrack)# permit any any
    
  4. Enable logging for filtered packets on a specific port, a set of ports, a LAG, or a VLAN.
    The following example enables logging on ports 1/1/1 and 1/1/3 for the MAC ACL mactrack.
    device(config-macl-maclog)#interface ethernet 1/1/1
    device(config-if-e1000-1/1/1)# mac access-group mactrack in logging enable
    device(config-if-e1000-1/1/1)# interface ethernet 1/1/3
    device(config-if-e1000-1/1/3)# mac access-group mactrack in logging enable
    device(config-if-e1000-1/1/3)# end
    device#
    The following example binds an IPv6 ACL to a LAG.
    device# configure terminal
    device(config)# interface lag 46
    device(config-lag-if-lg46)# ipv6 access-group v6track in logging enable
    device(config-lag-if-lg46)# exit
    device(config)#
    
    The following example binds an IPv4 ACL to a VLAN.
    device# configure terminal
    device(config)# vlan 222 by port
    device(config-vlan-222)# vlan 222 by port
    device(config-vlan-222)# router-interface ve 222
    device(config-vlan-222)# ip access-group v4track in logging enable
    device(config-vlan-222)# exit
    
    The following example binds acl1 to incoming traffic on selective ports in VLAN 10 (LAG 1 ports and Ethernet port 1/1/1) and enables logging for the ACL on the same interfaces.
    ICX(config)# vlan 10
    ICX(config-vlan-10)# tagged ethernet 1/1/1 ethernet 1/1/10 lag 1 lag 10
    ICX(config-vlan-10)# ip access-group acl1 in ethernet 1/1/1 logging enable
    ICX(config-vlan-10)# ip access-group acl1 in lag 1 logging enable 
    ICX(config-vlan-10)# exit
    ICX(config)#